Common Event Expression.


Published on May 29th, 2007

I am getting quite excited about some of the material I have been reading on Common Event Expression (pdf).  CEE is a desire to standardise the way that events are described.  I can see this being of significant advantage to sysadmins who need to produce large scale monitoring systems.

We already all use syslog-ng or rsyslogd or similar to aggregate our logs centrally, but it would be great to be able to aggregate logs inside our monitoring systems in such a way that when we add servers to our networks, any issues that they raise, in the application layer, or in hardware, are described to monitoring systems in a common and expected way.

If the taxonomy of error handling was equivalent on, say, routing kit as well as desktop systems, this allows sysadmins to deploy complex monitoring systems with less effort.  Understand how to handle a mistake with system-X and every single system you deploy from then on benefits from tried and tested monitoring and management.

Its early days for CEE, but I am optimistic about the benefits we could all realise if there was a desire to standardise logging.  Looking forward to what happens next.


Comments

Leave a Reply

You must be logged in to post a comment.